Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Он позволяет загружать и выгружать файлы, запускать процессы, выполнять PowerShell-скрипты, делать скриншоты и выполнять команды на других компьютерах локальной сети через SMB или WMI.
The tool, published on GitHub in September 2025, allows operators to upload, download, copy and delete files, execute commands, launch processes, and capture screenshots from compromised systems.
Второй запускает PowerShell-скрипт, который в конечном итоге загружает Ravage.
При запуске архива все файлы распаковываются во временный каталог. Затем выполняется batch-файл, который подготавливает интерпретатор и скрипт, после чего запускает последний.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source pentesting framework used in real-world attacks. The content says Ravage behaves more like a remote access tool than a full post-exploitation framework, enabling file upload/download, process execution, PowerShell execution, screenshots, and command execution on other computers over SMB or WMI.
Open-source post-compromise framework used by attackers as a remote access tool. It can upload/download/copy/delete files, launch processes, execute PowerShell received from C2, take screenshots, and run commands on hosts in the local network via SMB or WMI.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.